How to do the wireless client access control by MAC address when using SonicPoint VAP
03/26/2020 15 People found this article helpful 484,159 Views
Description
The video on YouTube is available.
This article shows you how to do the wireless client access control by MAC address when using SonicPoint VAP.
Resolution
In this case, the AP (access point) name is VAP, a mobile phone is connected to the AP.
- To do the access control when using VAP, please navigate to SonicPoint | Virtual Access Point . Click the edit button of the Virtual Accesss Point you are interested in at Virtual Access Points area | Click tab Advanced | Select Enable MAC Filter List.
2. To use global ACL settings, select Use Global ACL Settings. By default, this option is not checked.
To configure the Global ACL Settings, go to SonicPoint > SonicPoints | Click the edit button of the SonicPoint you are interested in at SonicPointNs area | ACL Enforcement can be configured in tab Radio Basic.
3. From the Allow List drop-down menu, select a MAC address group to automatically allow traffic from all
devices with MAC address in the group:
- Create new Mac Address Object Group The Add Address Object Group window displays.
- All MAC Addresses
NOTE: It is recommended that the Allow List be set to All MAC Addresses.
- Default SonicPoint ACL Allow Group
- Custom MAC Address Object Groups
4. From the Deny List drop-down menu, select a MAC address group from the drop-down menu to
automatically deny traffic from all devices with MAC address in the group.
NOTE: The Deny List is enforced before the Allow List.
- Create new Mac Address Object Group The Add Address Object Group window displays.
- No MAC Addresses
- Default SonicPoint ACL Deny Group
?NOTE: It is recommended that the Deny List be set to Default SonicPoint ACL Deny Group.
- Custom MAC Address Object Groups
To configure the Object Group, please follow below steps:
Step 1: Go to Firewall | Address Objects page. Edit Default ACL Deny Group or add a custom object group at Address Groups area.
Step 2: Click the edit button of the group | add/remove the relevant MAC address object of the wireless client.
How to test:
In this case, the mobile client MAC address has been added to the Default SonicPoint ACL Deny Group.
Selected Default SonicPoint ACL Deny Group from the Deny List, Mobile client disconnected from the AP.
Related Articles
Categories